Android中调用Upstox授权API报错UDAPI100016,重定向配置存疑
Upstox API Android授权登录UDAPI100016重定向问题
我正在尝试使用Upstox API实现授权登录,参考其官方认证文档。编写了仅包含登录按钮及其监听器的MainActivity代码,但点击登录按钮时应用抛出UDAPI100016错误,该错误由重定向问题导致。我已在Web应用中解决此错误,但Android端仍出现该问题,想确认我的重定向配置是否正确。
我的MainActivity代码
package com.apps.upstoxtrade; import androidx.appcompat.app.AppCompatActivity; import android.net.Uri; import android.os.Bundle; import android.view.View; import android.webkit.WebResourceRequest; import android.webkit.WebView; import android.webkit.WebViewClient; import android.widget.Button; import android.widget.Toast; public class MainActivity extends AppCompatActivity { private static String AUTH_URL = "https://api-v2.upstox.com/login/authorization/dialog"; private static final String RESPONSE_TYPE = "code"; private static final String CLIENT_ID = ""; private static final String REDIRECT_URI = "http://localhost:3000/redirect"; @Override protected void onCreate(Bundle savedInstanceState) { super.onCreate(savedInstanceState); setContentView(R.layout.activity_main); Button loginButton = findViewById(R.id.login); loginButton.setOnClickListener(new View.OnClickListener() { @Override public void onClick(View v) { // Call the login functionality performLogin(); } }); } private void performLogin() { WebView webView = findViewById(R.id.webView); webView.getSettings().setJavaScriptEnabled(true); // Handle URL loading within the WebView itself webView.setWebViewClient(new WebViewClient() { @Override public boolean shouldOverrideUrlLoading(WebView view, WebResourceRequest request) { String url = request.getUrl().toString(); // Check if the URL contains the authorization callback URL if (url.startsWith(AUTH_URL)) { // Extract the code parameter from the URL Uri uri = Uri.parse(url); String code = uri.getQueryParameter("code"); // Use the code to get the access token getAccessToken(code); // Return true to indicate that the URL has been handled return true; } return false; } }); AUTH_URL = AUTH_URL+"?response_type="+RESPONSE_TYPE+"&client_id="+CLIENT_ID +"&redirect_uri="+REDIRECT_URI; webView.loadUrl(AUTH_URL); } private void getAccessToken(String code) { // You can use any networking library of your choice to make an HTTP request to fetch the access token. // Here, I'm using a simple synchronous HTTP request for demonstration purposes. // Replace this with the actual HTTP request code using your preferred networking library. String accessToken = fetchAccessToken(code); // Handle the access token as needed (e.g., store it, use it for further API requests, etc.). if (accessToken != null) { // Access token obtained, do something with it Toast.makeText(this,accessToken,Toast.LENGTH_LONG); } else { // Access token retrieval failed } } // Replace this method with your actual HTTP request code to fetch the access token private String fetchAccessToken(String code) { // Replace this with the actual code to fetch the access token using the "code" parameter. // You can use libraries like Retrofit, OkHttp, etc., to make the HTTP request. // For this example, I'm simply returning a hardcoded access token for demonstration purposes. // Example response: {"access_token":"your_access_token","expires_in":3600,"scope":"read"} return "your_access_token"; } }
错误截图

问题分析与解决方案
1. 重定向URI配置问题
你当前使用的http://localhost:3000/redirect是Web应用的重定向地址,并不适配Android场景:
- Upstox API会验证请求中的重定向URI与开发者后台配置的完全一致,若后台仅配置了Web端地址,Android端使用相同地址会触发验证失败。
- 推荐为Android应用配置自定义Scheme(如
upstoxtrade://callback),这种方式更适合移动端跳转,避免localhost的兼容性问题。
2. WebView拦截逻辑错误
当前shouldOverrideUrlLoading方法判断的是URL是否以授权地址AUTH_URL开头,但登录成功后重定向的是你设置的REDIRECT_URI,所以拦截逻辑完全错误。修正代码如下:
@Override public boolean shouldOverrideUrlLoading(WebView view, WebResourceRequest request) { String url = request.getUrl().toString(); // 拦截重定向回调地址,而非授权地址 if (url.startsWith(REDIRECT_URI)) { Uri uri = Uri.parse(url); String code = uri.getQueryParameter("code"); if (code != null) { getAccessToken(code); return true; } } return false; }
3. AUTH_URL重复拼接问题
你在performLogin方法中直接修改静态变量AUTH_URL,导致第二次点击登录按钮时,URL会重复拼接参数,引发请求错误。应改为临时拼接:
// 不要修改静态AUTH_URL,每次请求临时拼接参数 String loginUrl = AUTH_URL + "?response_type=" + RESPONSE_TYPE + "&client_id=" + CLIENT_ID + "&redirect_uri=" + REDIRECT_URI; webView.loadUrl(loginUrl);
4. 自定义Scheme的Manifest配置
如果使用自定义Scheme作为重定向URI,需要在AndroidManifest.xml中为MainActivity添加intent-filter,确保应用能捕获该Scheme的跳转:
<activity android:name=".MainActivity"> <intent-filter> <action android:name="android.intent.action.VIEW" /> <category android:name="android.intent.category.DEFAULT" /> <category android:name="android.intent.category.BROWSABLE" /> <!-- scheme需与REDIRECT_URI中的一致,例如upstoxtrade --> <data android:scheme="upstoxtrade" /> </intent-filter> </activity>
最后,确保Upstox开发者后台中,你的Android应用条目下配置的重定向URI与代码中使用的完全一致,包括Scheme或域名路径。
内容的提问来源于stack exchange,提问作者Shadab
相关产品推荐
相关产品推荐

